Feature flags can become security states
A flag that turns something on for some users is an access control mechanism that nobody classified as one.
They are added quickly, accumulate, and eventually somebody discovers that a flag controls whether a check runs. Because they live outside the permission model, nobody reviews them, and changing one is often not treated as a change to production behaviour, which it plainly is.
More on Secure development
- Threat modelling asks how a design can fail before code existsBreak it on paper first
- Input validation defines what the application acceptsOne shape fits
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Security tests should exercise abuse casesThe load nobody specified
- Error handling should fail predictablyBreak the same way every time
